|
Novell NetWare Encoded Slash Directory Traversal Vulnerability
A vulnerability has been reported in some versions of Novell NetWare. This issue lies in the handling of some HTTP requests when a web server uses Perl as a handler. Reportedly, a directory traversal attack is possible. This is the result of an error in the handling of the URL encoded '\' character, which is encoded as '%5C'. Full technical details are not available. This issue has been reported in versions of NetWare using Perl 5.003. Reportedly, systems with Perl 5.6 installed are not vulnerable to this issue. |
|
|
Privacy Statement |